Primary authentication method and apparatus
Abstract
This application provides a primary authentication method and an apparatus. The method includes: An AMF receives, from a home network device, a first authentication request message for triggering a primary authentication procedure, the primary authentication procedure is used to perform primary authentication on a terminal device, and the home network device is a network device in a home network of the terminal device. The AMF sends a first authentication response message to the home network device when rejecting the triggering of the primary authentication procedure, where the first authentication response message includes first rejection cause information indicating a cause for rejecting the triggering of the primary authentication procedure.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A primary authentication method, comprising:
receiving, by an access and mobility management function device, a first authentication request message from a home network device, wherein the first authentication request message comprises an identifier of a terminal device, the first authentication request message is used to trigger a primary authentication procedure on the terminal device, and the home network device is a network device in a home network of the terminal device; and when the access and mobility management function device rejects the triggering of the primary authentication procedure, sending, by the access and mobility management function device, a first authentication response message to the home network device, wherein the first authentication response message comprises first rejection cause information, and the first rejection cause information indicates a cause for rejecting the triggering of the primary authentication procedure.
2 . The method according to claim 1 , wherein the method further comprises:
determining, by the access and mobility management function device based on the first authentication request message, to reject the triggering of the primary authentication procedure on the terminal device.
3 . The method according to claim 2 , wherein the determining, by the access and mobility management function device based on the first authentication request message, to reject the triggering of the primary authentication procedure comprises:
if determining, based on the identifier, that a primary authentication procedure has been triggered on the terminal device within preset duration, determining, by the access and mobility management function device, to reject the triggering of the primary authentication procedure.
4 . The method according to claim 2 , wherein the determining, by the access and mobility management function device based on the first authentication request message, to reject the triggering of the primary authentication procedure comprises:
if determining, based on the identifier, that the home network device does not have permission to trigger the primary authentication procedure, determining, by the access and mobility management function device, to reject the triggering of the primary authentication procedure.
5 . The method according to claim 4 , wherein the determining, by the access and mobility management function device based on the identifier, that the home network device does not have permission to trigger the primary authentication procedure comprises:
obtaining, by the access and mobility management function device, subscription data of the terminal device based on the identifier; and determining, by the access and mobility management function device based on the subscription data, that the home network device does not have the permission to trigger the primary authentication procedure.
6 . The method according to claim 5 , wherein the subscription data indicates that the terminal device does not support at least one of a steering of roaming procedure, a user equipment parameter update procedure, or an authentication and key management for applications procedure.
7 . The method according to claim 2 , wherein the determining, by the access and mobility management function device based on the first authentication request message, to reject the triggering of the primary authentication procedure comprises:
if determining, based on the identifier, that a primary authentication procedure is being executed on the terminal device, determining, by the access and mobility management function device, to reject the triggering of the primary authentication procedure.
8 . The method according to claim 7 , wherein the determining, by the access and mobility management function device based on the identifier, that a primary authentication procedure is being executed on the terminal device comprises:
when the access and mobility management function device has triggered the primary authentication procedure on the terminal device corresponding to the identifier, and receives no corresponding authentication result, determining, by the access and mobility management function device, that the primary authentication procedure is being executed on the terminal device.
9 . A primary authentication method, comprising:
receiving, by a user data management device, a first request message from an authentication server function device, wherein the first request message comprises an identifier of a terminal device, and the first request message is used to request a first authentication vector for the terminal device; and when rejecting to return the first authentication vector, sending, by the user data management device, a first response message to the authentication server function device, wherein the first response message comprises second rejection cause information, and the second rejection cause information indicates a cause for rejecting to return the first authentication vector.
10 . The method according to claim 9 , wherein the method further comprises:
determining, by the user data management device based on the first request message, to reject to return the first authentication vector.
11 . The method according to claim 10 , wherein the determining, by the user data management device based on the first request message, to reject to return the first authentication vector comprises:
if determining, based on the identifier, that a primary authentication procedure has been triggered on the terminal device within preset duration, determining, by the user data management device, to reject to return the first authentication vector.
12 . The method according to claim 10 , wherein the first request message comprises the identifier of the terminal device, and the determining, by the user data management device based on the first request message, to reject to return the first authentication vector comprises:
if determining, based on the identifier, that a primary authentication procedure is being executed on the terminal device, determining, by the user data management device, to reject to return the first authentication vector.
13 . The method according to claim 12 , wherein the determining, by the user data management device based on the identifier, that a primary authentication procedure is being executed on the terminal device comprises:
when the user data management device has sent a second authentication vector used to authenticate the terminal device corresponding to the identifier, and receives no authentication result confirmation message corresponding to the second authentication vector, determining that the primary authentication procedure is being executed on the terminal device.
14 . A communication apparatus, comprising at least one processor coupled to at least one memory storing instructions and configured to execute the instructions to cause the apparatus to:
receive a first authentication request message from a home network device, wherein the first authentication request message comprises an identifier of a terminal device, the first authentication request message is used to trigger a primary authentication procedure on the terminal device, and the home network device is a network device in a home network of the terminal device; and when rejecting the triggering of the primary authentication procedure, send a first authentication response message to the home network device, wherein the first authentication response message comprises first rejection cause information, and the first rejection cause information indicates a cause for rejecting the triggering of the primary authentication procedure.
15 . The communication apparatus according to claim 14 , wherein the instructions further cause the apparatus to determine, based on the first authentication request message, to reject the triggering of the primary authentication procedure on the terminal device.
16 . The communication apparatus according to claim 14 , wherein the instructions cause the apparatus to determine to reject the triggering of the primary authentication procedure on the terminal device by determining, based on the identifier, that a primary authentication procedure has been triggered on the terminal device within preset duration.
17 . The communication apparatus according to claim 14 , wherein the instructions cause the apparatus to determine to reject the triggering of the primary authentication procedure on the terminal device by determining, based on the identifier, that the home network device does not have permission to trigger the primary authentication procedure.
18 . The communication apparatus according to claim 14 , wherein the instructions cause the apparatus to determine to reject the triggering of the primary authentication procedure on the terminal device by:
obtaining subscription data of the terminal device based on the identifier; and determining, based on the subscription data, that the home network device does not have the permission to trigger the primary authentication procedure.
19 . The communication apparatus according to claim 18 , wherein the subscription data indicates that the terminal device does not support at least one of a steering of roaming procedure, a user equipment parameter update procedure, or an authentication and key management for applications procedure.
20 . The communication apparatus according to claim 14 , wherein the instructions cause the apparatus to determine to reject the triggering of the primary authentication procedure on the terminal device by determining that the primary authentication procedure has been triggered on the terminal device corresponding to the identifier, and no corresponding authentication result is received.Join the waitlist — get patent alerts
Track US2024244432A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.